Mellow.Family

Privacy policy

Last updated August 16, 2026 · applies to beta registration and the public demo

Beta applications and account data

Account and service data includes your email, authentication records, messages and attachments, calendars, expenses and receipts, journal entries, vault files, professional grants, call-consent records and recordings, export snapshots, timestamps, delivery states, and security audit events.

A beta application contains only your name, email, parent or professional role, state or country, feedback availability, consent versions, timestamps, and application status. Do not submit child names, case details, court information, or sensitive family narratives through the beta form.

Public demo

The public demo uses fictional information and browser-only demo state. It does not connect to a family account, Google Calendar, Stripe, or Mellow family-record tables.

When you deliberately ask the demo version of Mellow Coach to review fictional draft text, that draft is sent to Google Gemini to return the requested rewrite. Mellow does not store the draft or response. For security and abuse prevention, we retain a keyed hash of the network address, request identifier, demo action, model, status, safety outcome, latency, and token counts for no more than 48 hours. The raw network address is not stored in demo telemetry.

Google Calendar data

Google Calendar connection is not part of the public demo and remains unavailable while provider review is pending.

If you connect Google Calendar, Mellow Family requests read-only access to your primary calendar. For the visible overlay, it accesses the Google event ID, title, description, start value, and end value. Mellow does not write to Google Calendar.

Overlay events are fetched from Google on demand and are not cached by the application. Mellow stores an encrypted refresh token, the granted scopes, connection state, and any account identifier returned by Google so it can maintain the connection. It does not keep a persistent copy of an event unless you deliberately select Copy into Mellow. A copied event becomes a Mellow record and follows Mellow's retention rules.

Disconnecting Google Calendar attempts to revoke the token with Google, removes the locally stored token, and immediately prevents further Google access. You can also revoke access from your Google Account permissions.

Google API Limited Use

Mellow Family's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google data is not sold, used for advertising, used for credit or lending decisions, or used to train generalized artificial-intelligence models. It is shared only as needed to provide the user-facing calendar feature, protect security, comply with law, or for another narrowly permitted purpose under Google's policy.

How we use and share information

We use information to provide, secure, support, and improve the features you request; process applications and payments; maintain records; communicate service notices; prevent abuse; and comply with law. Marketing email requires separate optional consent and is not required to apply or use the service.

Your family records are visible to family-space members and people you explicitly authorize, such as a professional receiving read-only access. We do not sell personal information or show advertising.

Supabase provides database, authentication, and storage infrastructure; Stripe processes payments; and Resend delivers transactional email. They receive only the information necessary to perform those services under their applicable terms and safeguards. Stripe, not Mellow Family, stores payment-card details.

AI features

When you request Mellow Coach or receipt OCR, the content needed for that request is sent to the configured AI provider to return the result. Mellow does not use family content to train its own models or permit family content to train generalized AI models. Provider processing is governed by the applicable service agreement and subprocessor disclosures.

Retention, deletion, and shared records

Unneeded beta screening fields are deleted 12 months after launch or earlier after a valid deletion request. We may retain limited suppression, consent, entitlement, security, and financial records when necessary to honor choices, provide benefits, prevent abuse, or meet legal obligations.

Sent messages and journal entries are append-only by design; calendar and expense corrections create revisions. Closing an account does not erase shared records from another family-space member. Copied Google events follow these same Mellow retention rules.

You may request access, correction, disconnection, or deletion by emailing privacy@mellow.family. We verify requests and respond subject to shared-record integrity and applicable legal retention duties.

Security

Data is encrypted in transit and at rest. Access is restricted by row-level database controls, service roles, authorization checks, and logged administrative operations. No security program can guarantee absolute protection.

Contact

Privacy questions and requests: privacy@mellow.family.